Skip to content

[GHSA-h524-452v-82p9] Decoding a maliciously-crafted MIME header containing... - #7909

Closed
tarampampam wants to merge 1 commit into
tarampampam/advisory-improvement-7909from
tarampampam-GHSA-h524-452v-82p9
Closed

tarampampam wants to merge 1 commit into
tarampampam/advisory-improvement-7909from
tarampampam-GHSA-h524-452v-82p9

Conversation

@tarampampam

Copy link
Copy Markdown

Updates

  • Affected products
  • Summary

Comments
Affected versions and package name updated

Copilot AI review requested due to automatic review settings June 7, 2026 09:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Updates the GHSA advisory metadata by adding a summary and populating the affected package/range information.

Changes:

  • Updated the advisory modified timestamp
  • Added a summary field
  • Filled in the affected section with Go ecosystem package/range and last-known affected range metadata

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

"aliases": [
"CVE-2026-42504"
],
"summary": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU. Updated 3 days",

@tarampampam tarampampam Jun 7, 2026

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot remove it

@github-actions
github-actions Bot changed the base branch from main to tarampampam/advisory-improvement-7909 June 7, 2026 09:02
"aliases": [
"CVE-2026-42504"
],
"summary": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU. Updated 3 days",

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
"summary": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU. Updated 3 days",
"summary": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU",

@github-actions

Copy link
Copy Markdown

👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.

@github-actions github-actions Bot added the Stale label Jul 11, 2026
@tarampampam

Copy link
Copy Markdown
Author

Up

@github-actions github-actions Bot removed the Stale label Jul 12, 2026
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.

@github-actions github-actions Bot added the Stale label Aug 3, 2026
@shelbyc

shelbyc commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

👋 Hi @tarampampam, unfortunately we can't accept this PR because the GitHub Advisory Database doesn't support advisories for issues in the Go standard library, only packages on pkg.go.dev. Thanks for your interest in GHSA-h524-452v-82p9 and the Go ecosystem!

@shelbyc shelbyc closed this Aug 5, 2026
@github-actions
github-actions Bot deleted the tarampampam-GHSA-h524-452v-82p9 branch August 5, 2026 21:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants